Web3 gives you real ownership of your assets, but it also means you are your own bank. One wrong click or signature can drain your wallet. This guide gives you clear, practical rules to stay safe with wallets, dApps, and onchain activity.
1. Core mindset: “Verify, don’t trust”
In Web3, your default should be zero trust:
• Don’t trust links from DMs, replies, or random comments.
• Don’t trust websites just because they look professional.
• Don’t trust transactions just because your wallet shows them.
If you feel rushed, scared, or pressured to act “right now”, stop.
Urgency and fear are the main tools of scammers.
2. Before connecting your wallet
Connecting your wallet is like opening your front door. Before you click “Connect wallet”:
Check the URL
- Is the domain spelled exactly right?
- Real: app.uniswap.org
- Fake: app-uniswap.org.co, uni-swap.app, etc.
- Avoid clicking shortened links if you don’t fully trust the source.
Find official links yourself
- Go to the project’s official X/Twitter, docs, or website and click links from there.
- Ignore “support” links sent in replies, comments, or DMs.
Ask why you are connecting
- Do you clearly understand what the site does?
- If not, don’t connect your main wallet.
3. Understand what you’re signing
Most “hacks” are actually people signing something they don’t understand. A signature can:
- Give a contract permission to spend all of a token.
- Move your NFTs.
- Approve complex actions you didn’t intend.
Good habits:
• Read the summary in your wallet before you sign.
• If your wallet offers a transaction simulator, check what it says will happen.
• If the text is long, weird, or unrelated to what you’re doing → reject.
No legit project needs you to sign a strange message to “fix”, “restore” or “unlock” your funds.
4.Hot, cold, and burner wallets
Hot wallet
- Browser or mobile wallet (MetaMask, Rabby, Phantom, etc.).
- Always online.
- Use for: daily DeFi, NFTs, airdrops.
- Risk: easiest to attack if you click bad links or sign bad approvals.
Cold wallet (hardware)
- Ledger, Trezor, Keystone, etc.
- Keys stored offline.
- Use for: long‑term holdings and larger amounts.
- Rule: don’t connect it to random new dApps.
Burner wallet
- A disposable hot wallet.
- Holds only a small amount of funds.
- Use for: testing new dApps, risky mints, unknown airdrops.
5. How to create and use a burner wallet (step‑by‑step)
- Open your wallet app/extension.
- Create a new wallet/account (separate from your main one).
- Write the new seed phrase on paper (not in screenshots or notes apps).
- Send only a small amount of crypto to it (gas + what you plan to risk).
- Use this burner wallet for:
- New/unknown dApps
- Experimental farms
- Risky NFT mints or airdrops
If the site is malicious, it can only drain the burner, not your main savings.
6. How to check if a site or project is legit
Before you interact with a project:
• History: has it been around for a while, or did everything appear yesterday?
• Team: is there a public or at least consistent identity, or is it totally anonymous with no trace?
• Link consistency: do the links on X, the website, and the docs all match?
• Code & audits: is there open‑source code, audits, or any technical transparency?
If something feels off, don’t interact. There is always another opportunity in crypto.
7. Common scam red flags Be extra careful if you see:
- Anonymous team + no history + big promises.
- Too‑good‑to‑be‑true rewards (“10x APY in 1 day”, “guaranteed returns”).
- Fake urgency (“connect in 5 minutes or your funds are lost!”).
- Unsolicited DMs from “support” or “admins”.
- Copied UI/website of a famous protocol with a slightly different URL.
Two or more of these together usually means: walk away.
8. Popular scam types in Web3
• Phishing links: fake websites that look real and try to steal your seed or make you sign bad txs.
• Fake airdrops: sites claiming you can “claim” rewards if you connect and sign, or even send tokens first.
• Address poisoning: scammer sends you tiny tokens from an address that looks like one you know, hoping you later copy the wrong one from your history.
Defenses:
• Only use links from official sources.
• Never pay to receive an airdrop.
• Always check the first and last 4 characters of the address before sending funds.
9. Revoke old approvals – and do it regularly
Every time you use DeFi or NFTs, you grant token approvals to contracts. Over months, these approvals pile up.
If an old contract you once used is exploited, your tokens can be at risk.
What to do:
• Use an approval checker (there are several popular ones).
• Connect your wallet and review which contracts can spend your tokens.
• Revoke permissions you no longer need.
Thinking of it like cleaning old keys you handed out: if someone finds one later, they can still open the door.
10. Seed phrase safety (non‑negotiable rules)
Your seed phrase is the master key to your wallet.
Never:
• Type it into any website or Google form.
• Paste it into chats, email, or “support” tickets.
• Store it in screenshots, notes apps, or cloud drives.
Do:
• Write it on paper (or metal backup) and store it safely.
• Make one or two secure copies in case of loss or damage.
• Consider using a hardware wallet so the seed never leaves the device.
If anyone ever asks for your seed phrase, they are a scammer. No exceptions.
11. If you think your wallet is compromised
Act fast:
- Stop interacting with suspicious sites immediately.
- Create a new wallet (preferably on a fresh device).
- Move remaining funds and valuable NFTs to the new wallet.
- Use approval tools to revoke approvals from the old wallet if possible.
- Treat the old wallet as burned for serious use.
- Warn friends/communities if a scam link spread via a shared group.
Speed can be the difference between losing everything and limiting the damage.
12. Conclusion: security is a habit
Web3 security isn’t about being paranoid; it’s about having simple habits and sticking to them:
• Verify links and URLs.
• Read and understand what you sign.
• Use burner wallets for risky stuff.
• Keep large amounts on hardware wallets.
• Regularly revoke old approvals.
• Protect your seed phrase like real cash.
If you treat every click and signature as if real money is at stake—because it is—you will already be safer than most people onchain.









Latest comments
0